Re: [DNSOP] Fwd: New Version Notification for draft-ietf-dnsop-algorithm-update-01.txt

Matthew Pounsett <matt@conundrum.com> Wed, 13 June 2018 11:27 UTC

Return-Path: <matt@conundrum.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58959130E0D for <dnsop@ietfa.amsl.com>; Wed, 13 Jun 2018 04:27:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.609
X-Spam-Level:
X-Spam-Status: No, score=-2.609 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, T_DKIMWL_WL_MED=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=conundrum-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UD1SGEn4svwm for <dnsop@ietfa.amsl.com>; Wed, 13 Jun 2018 04:27:25 -0700 (PDT)
Received: from mail-it0-x22f.google.com (mail-it0-x22f.google.com [IPv6:2607:f8b0:4001:c0b::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EEB391292F1 for <dnsop@ietf.org>; Wed, 13 Jun 2018 04:27:24 -0700 (PDT)
Received: by mail-it0-x22f.google.com with SMTP id 76-v6so3217912itx.4 for <dnsop@ietf.org>; Wed, 13 Jun 2018 04:27:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=conundrum-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=wZ8ydHZCP922eQkDUYrZvBVxOu8hh8Cgu9Ln8//yRoA=; b=FYZ3eJ0DoG6Z1PGwur1IdWIRVa67te98s88DC152e92eToJ6BGnF+Zl9k9Ho7iR/HQ Q4WeyhgZiOmnFoo5SFXT5tV10kkYDebQWmkyaO23KH9A/1JzMbgy4Nh4xlAw6XpPsvG6 O9xNaK/uAj8GQrUHSQbyvOqQc4x+lyTu6oR/H7ul2CYTVJR96+BAa+FWDk+sm5DzVEiT MvtiA7n4vI/CW880xMP5PqIPNP4TB2XdzQ0bAI1gHc8J8xO2Ybk9TeVAyLGC0LKIaygz wtJfUpyX8drxtp7yDcuS4RgiX/gqD17II7aVdJF7B/9AgVV30HT6Ndm3m1Bsq7vVFX27 TEHw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=wZ8ydHZCP922eQkDUYrZvBVxOu8hh8Cgu9Ln8//yRoA=; b=QnnAfva2GHn1KvffYmPjRXsye5einOQkjnR5CkkKI8n+V81vbBpj/29SDsvANKWaQC gspiTBLhw8oaflJm2o2Nzm8fzphRKzIpBrgthPilmP0AI2jLQLi1ZnX63/OKfNPiBFcF EUTSDrRrVj8zvkw8KDDXnKMjqglqrnHtuymXKPnG6uIgFGPA5L9WHUhOyLWR9xphkpnp P3nDWq/Pw7GjEWyfPqsqGE0o9AhehIzKSxUEJh7hS9nFmwJWDC/9ku3HxWiWtcDJegDz tVRV9/rO9rTcJGapz8fdTS8f5bUuQkF3c9dSj3XmuNHtsuMO2Hrg2oD6G7mBUmOzZlB4 8lcA==
X-Gm-Message-State: APt69E0CFDmTjI1n418yCF1nsaCaMTfcbLL4f8+msoELMJwfTfNbTTut IV1vIrNAwPXZhqykjKHPp3Vdl+Ps5HkUROso9S3Yil5R
X-Google-Smtp-Source: ADUXVKI52Co5MA7MKjFIFhJWSqpgxB5HQeXL0RpvLx+1B19hiox5e0emdA7PFc67txjPCb+s31kzjGdtzstRwJyjxFA=
X-Received: by 2002:a24:6514:: with SMTP id u20-v6mr4464883itb.38.1528889243668; Wed, 13 Jun 2018 04:27:23 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a02:5cd1:0:0:0:0:0 with HTTP; Wed, 13 Jun 2018 04:27:22 -0700 (PDT)
In-Reply-To: <20180607193355.GF3322@mournblade.imrryr.org>
References: <152822474090.19277.2490524843716126021.idtracker@ietfa.amsl.com> <D1867A13-540C-4154-B70A-C057428DFA26@isc.org> <20180607063933.GD3322@mournblade.imrryr.org> <alpine.LRH.2.21.1806071357470.31594@bofh.nohats.ca> <20180607193355.GF3322@mournblade.imrryr.org>
From: Matthew Pounsett <matt@conundrum.com>
Date: Wed, 13 Jun 2018 07:27:22 -0400
Message-ID: <CAAiTEH8-muq1xje5gVO0_wpB8AELA0bPQ+x_oXRkgJRc7r4Y1w@mail.gmail.com>
To: dnsop <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000454710056e84449c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/TFpk8tvqG94N2DTtu6uhlRTXDxY>
Subject: Re: [DNSOP] Fwd: New Version Notification for draft-ietf-dnsop-algorithm-update-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Jun 2018 11:27:29 -0000

On 7 June 2018 at 15:33, Viktor Dukhovni <ietf-dane@dukhovni.org> wrote:

> >
> > I hope it is now clearer why we are doing this?
>
> Well, I see that we end up with a bit less code-point diversity,
> but in this case 8/10 are barely different and require the same
> supporting code.  So while I'm not strongly advocating 10, I see
> it just a "tweak" of 8, and would expect to not differentiate
> between them, use either, interoperate with neither or both...
>
> Again, this comment is not an objection just saying that I would
> have treated 8 and 10 as interchangeable.
>
> Except that they are not interchangeable, and algorithm rolls are
operationally expensive.  Anyone doing an algo roll from 8 to 10 is less
likely to want to do one again any time soon. Since there is little gain
from moving to 10, it's better to discourage use of 10 in order to
encourage–and make it easier for–operators to use their algo rolls to move
to ECC instead.